Author Topic: Mr Clean's dirt  (Read 184284 times)

0 Members and 1 Guest are viewing this topic.

January 04, 2010, 04:42:10 pm
Reply #315

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://pro-defenderq.com/download/Setup77742_2042-4.exe

$ dig pro-defenderq.com +short
66.232.102.69
91.212.226.188

$ md5sum Setup77742_2042-4.exe
7d311af2a4fa1918560e0ea9b7daf368  Setup77742_2042-4.exe

http://www.virustotal.com/analisis/262dd0615db46ac333e5f803f30ac9b0331de76eb0c22908dc769ac511238f64-1262622328 2/41
http://anubis.iseclab.org/?action=result&task_id=1fadcaef59f801494cd866a57a1655f43&format=html


pro-defenderq.com


January 05, 2010, 11:00:06 pm
Reply #316

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://www1.hot-cleanofyourpc.com/build7_287.php?cmd=getFile&counter=1&p=p52dcWpsb1%2FCj8bYboBwgHle0KCfZ1bVoKDb2YmHWJjOxaCbkX1%2Ba16orKWeZpWeZWhjlWOZmI6Io6THodjXoGJdo3OL1cytnpl2Wp6dpJ6eU9rPlqdqWqaroV6UZmKdX5yXmWldlZmi


$ dig www1.hotcleanof-yourpc.net +short
89.248.160.157

$ md5sum setup_build7_287.exe
3dc2cedece109d0353a94da09d8120c1  setup_build7_287.exe

http://www.virustotal.com/analisis/18ddb7dc6ff61ddcada96d65e7c5a0b80009823f3609683dc6fb6f798777cefd-1262732306 8/41


www1.hotcleanof-yourpc.net


January 08, 2010, 06:55:14 pm
Reply #317

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://www1.best-pcprotection.com/build19102_287.php?cmd=getFile&counter=9&p=p52dcWpsb1%2FCj8bYboBwgHle0KCfYWmXXZWK0qR0qay9sYmbm5h2lpd9fXCHodjSbpZelmZumo6TYmebU9bYxKWspXOL0qBfpp2toJ1xXp%2FKmcmjV6aWmal1iqHVbWGYY5WdmmZoam6LxMZ2

Referer: hxxp://www1.protect-my-system.net/?p=p52dcWpsb1%2FCj8bYboBwgHle0KCfYWmXXZWK0qR0qay9sYmbm5h2lpd9fXCHodjSbpZelmZumo6TYmebU9bYxKWspXOL0qBfpp2toJ1xXp%2FKmcmjV6aWmal1iqHVbWGYY5WdmmZoam6LxMZ2

$ dig www1.best-pcprotection.com +short
89.248.160.158

$ dig www1.protect-my-system.net +short
89.248.160.153

$ md5sum packupdate_build19102_287.exe
4912961c36306d156e4e2b335c51151b  packupdate_build19102_287.exe

http://www.virustotal.com/analisis/1047249ad5922274348d1fbc13ef675ee6aa13a3a4d7c03e646a2c4587a1bb9c-1262976540 7/41


best-pcprotection.com
protect-my-system.net


January 08, 2010, 08:40:33 pm
Reply #318

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://statcntr.com/news/ld.php?e=pdf

$ dig statcntr.com +short
193.104.22.153

$ md5sum op.exe
c803fc126b9a63a25a48475b52c4caea  op.exe

http://www.virustotal.com/analisis/6e008eaa0e84abef124413aa9ac940523a005c77d6c9055fbc0b8ae6875d83b1-1262982756 14/41


statcntr.com



January 12, 2010, 10:24:07 pm
Reply #319

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://www1.best-pcdefender.com/build6_287.php?cmd=getFile&counter=1&p=p52dcWpsb1%2FCj8bYbnx9d3le0KCfZlbVoKDb2YmHWJjOxaCbkX1%2Ba16orKWek5WdZZZjmmRqlWCIo6THodjXoGJdo3PVysatp6aep1ijnlnMkt3ZmZmOVJWn0JKCoKLLlNHF0aVdpp%2FZzch2WJqioJ1xXq%2FKktujV6SgcWNqmmCVYmWdX5SKxpR0

$ dig www1.best-pcdefender.com +short
89.248.160.153

$ md5sum packupdate_build6_287.exe
9bc59c7fab03e27a0d527fbca352099c  packupdate_build6_287.exe

http://www.virustotal.com/analisis/b291101a733cb656f39c3b85a887e2f5b9730a8564c09d3d80b49560c23f0458-1263334930 1/41


best-pcdefender.com


January 13, 2010, 03:03:53 am
Reply #320

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://3-onlinescanner.com/download/Setup_2002-8.exe

$ dig 3-onlinescanner.com +short
66.232.102.65
94.228.208.59

$ md5sum Setup_2002-8.exe
2e1ab9f8c723b8b657b17d77e5c7e84e  Setup_2002-8.exe

http://www.virustotal.com/analisis/b76d41e3233b1eaceacbdd4a61b726c00c416903eaac88d311b89633056e1d65-1263338143 3/41


3-onlinescanner.com


January 13, 2010, 07:38:37 pm
Reply #321

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://kill-spywarem2.com/download/Setup_40s5.exe

$ dig kill-spywarem2.com +short
193.104.22.201
213.175.221.46

$ md5sum Setup_40s5.exe
abf693010b11ff7c6ac3ec297fc99904  Setup_40s5.exe

http://www.virustotal.com/analisis/a1c0b23dcfa9bc10f2cdb55c1358c5bd7c01c903a2aa9829f205b73137d30e89-1263410660 4/40


kill-spywarem2.com


January 13, 2010, 07:39:37 pm
Reply #322

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://kill-spywarem7.com/download/Setup_103.exe

$ dig kill-spywarem7.com +short
193.104.22.201
213.175.221.46

$ md5sum Setup_103.exe
abf693010b11ff7c6ac3ec297fc99904  Setup_103.exe

http://www.virustotal.com/analisis/a1c0b23dcfa9bc10f2cdb55c1358c5bd7c01c903a2aa9829f205b73137d30e89-1263410660 4/40


kill-spywarem7.com


January 15, 2010, 12:48:19 pm
Reply #323

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331

January 18, 2010, 03:48:14 am
Reply #324

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://www.ancisoft.com/file/xkvpsetup.exe

$ dig www.ancisoft.com +short
221.231.138.89

$ md5sum xkvpsetup.exe
5fb51d678665b42c6cb2e34ae73346fe  xkvpsetup.exe

http://www.virustotal.com/analisis/8f517de0a8b8f38571ab1708d4f67b7e046018bc64121644a7b2470b16f59147-1263786171 13/41


ancisoft.com


January 19, 2010, 04:01:02 pm
Reply #325

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://www.teu8.cn/c.exe

$ dig www.teu8.cn +short
174.139.3.50

$ md5sum c.exe
e7bf0e74a9ab882b0430395f1c196913  c.exe

http://www.virustotal.com/analisis/b8c9ac6813ccae8f81abc9ab7653e736a81b3ef1f11a3810c1cc04d6f4310ec7-1263916378 31/41


teu8.cn


January 19, 2010, 10:24:41 pm
Reply #326

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Look at the Referrer -- "a.photobucket.com"

Code: [Select]
192.168.1.1 - - [19/Jan/2010:21:53:52 +0000] "GET http://google.com.analytics.sbeqpirscun.com/nte/TREST11.exe HTTP/1.1" - - "http://a.p
hotobucket.com/hserver/random=185831/pageid=307661826/area=PB_AL_U_FULL/aamsz=BANNER/age=25/zip=19506/gender=F/login=Y/Camera=ResearchIn
MotionBlackBerry8110,NIKONCORPORATIONNIKOND3,CanonCanonPowerShotA520/mobile_carrier=AT&T/email_domain=COM/anprice=85" "Mozilla/4.0 (comp
atible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648)"

$ dig google.com.analytics.sbeqpirscun.com +short
64.150.187.239


http://www.virustotal.com/analisis/c4a5e9d4635e863ebcea026319206143a99b4c301b9c68cf2d6aa7fc8fb0b93b-1263934871 4/40



google.com.analytics.sbeqpirscun.com



January 25, 2010, 06:26:45 pm
Reply #327

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://statacon.com/news/ld.php?e=pdf

$ dig statacon.com +short
193.104.22.153

$ md5sum op.exe
199f7c473276ab2d2ea1d159056ec610  op.exe

http://www.virustotal.com/analisis/0329c5130681d0f1e56c7964c8cf121d222a8c76f0dae2ab2a26c01f8f0e7472-1264443673 3/39


statacon.com


February 02, 2010, 05:42:31 pm
Reply #328

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://google.analytics.com.jestywtvadgj.info/kav/kav3.exe

$ dig google.analytics.com.jestywtvadgj.info +short
174.142.53.148

http://www.virustotal.com/analisis/ff5fbf07fe9d1d8ed3bd287327e7b215a9e400ed4fe0037a37f0854739779a12-1265131372 3/40

http://wepawet.iseclab.org/view.php?hash=a0e3e250e1cf7f02c54258507edf7178&t=1265131760&type=js


google.analytics.com.jestywtvadgj.info


February 03, 2010, 01:58:42 am
Reply #329

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://banner.titanpoker.com/installer/casino/SetupPoker_f80ad.exe

$ dig banner.titanpoker.com +short
69.90.74.226
66.199.155.194

$ md5sum SetupPoker_f80ad.exe
1dbf65e403c23a53bf349b976aaea44a  SetupPoker_f80ad.exe

http://www.virustotal.com/analisis/82fe9f1fe166e1c7ea22b38c5c23d1aaa0273f6ec09c3bade2205a2122b16a75-1265161220 12/39


titanpoker.com